7.5
CVSSv2

CVE-2017-7481

Published: 19/07/2018 Updated: 04/08/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ansible prior to 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift container platform 3.3

redhat openshift container platform 3.4

redhat openshift container platform 3.5

redhat openstack 10

redhat openstack 11

redhat storage console 2.0

redhat virtualization 4.1

redhat virtualization manager 4.1

redhat gluster_storage 3.2

redhat ansible engine

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #862666 ansible: CVE-2017-7481: Security issue with lookup return not tainting the jinja2 environment Package: src:ansible; Maintainer for src:ansible is Harlan Lieberman-Berg <hlieberman@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 15 May 2017 14:30:02 UTC Se ...
Several security issues were fixed in Ansible ...
Synopsis Important: ansible security update Type/Severity Security Advisory: Important Topic An update for ansible is now available for Red Hat Gluster Storage 32 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Synopsis Important: ansible security update Type/Severity Security Advisory: Important Topic An update for ansible is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVS ...
Synopsis Important: ansible security update Type/Severity Security Advisory: Important Topic An update for ansible is now available for Red Hat OpenStack Platform 110 (Ocata)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS ...
Synopsis Important: ansible security update Type/Severity Security Advisory: Important Topic An update for ansible is now available for Red Hat Storage Console 2 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Important: ansible and openshift-ansible security and bug fix update Type/Severity Security Advisory: Important Topic An update for ansible and openshift-ansible is now available for Red Hat OpenShift Container Platform 32, Red Hat OpenShift Container Platform 33, Red Hat OpenShift Container Plat ...
An input validation flaw was found in Ansible, where it fails to properly mark lookup-plugin results as unsafe If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution By default, the jinja2 templating language is now marked as 'unsafe' ...